On Saturday, April 14, 2018 10:53:58 PM CDT Chris Lamb wrote:
> Can you
> hunt around for any file you think matches?

ctime of /etc/inittab or /root/.profile might work.

ctime candidates attached.

-- 
Boyd Stephen Smith Jr.                   ,= ,-_-. =.
b...@iguanasuicide.net                   ((_/)o o(\_))
ICQ: 514984 YM/AIM: DaTwinkDaddy         `-'(. .)`-'
http://iguanasuicide.net/                    \_/
% find / \( -ctime +3756 -not -ctime +3787 -ls \) -o \( -name home -type d -prune \) 2>&- > find-install-ctime
     6517      0 lrwxrwxrwx   1 root     root           20 Dec 17  2007 /bin/mt -> /etc/alternatives/mt
     8998      0 lrwxrwxrwx   1 root     root           13 Dec 17  2007 /etc/X11/X -> /usr/bin/Xorg
     8883      4 -rw-r--r--   1 root     root          319 Feb 13  2007 /etc/X11/Xresources/x11-common
     7387      8 -rw-r--r--   1 root     root         6270 Sep 30  2006 /etc/X11/fonts/misc/xfonts-base.alias
     8902     28 -rw-r--r--   1 root     root        28252 Jun 30  2006 /etc/X11/fonts/Type1/gsfonts-x11.alias
     8901      8 -rw-r--r--   1 root     root         7439 Jun 30  2006 /etc/X11/fonts/Type1/gsfonts-x11.scale
     9629      4 -rw-r--r--   1 root     root         2654 Nov 18  2006 /etc/X11/fonts/Type1/xfonts-scalable.scale
     8880      4 -rw-r--r--   1 root     root          166 Feb 13  2007 /etc/X11/Xsession.d/99x11-common_start
     7264      4 -rw-r--r--   1 root     root         2982 Dec 18  2007 /etc/X11/xorg.conf.20071218003554
     8881      4 -rw-r--r--   1 root     root          265 Feb 13  2007 /etc/X11/Xsession.options
     8962      4 -rw-r--r--   1 root     root         3184 Jan 12  2007 /etc/X11/app-defaults/Viewres
     8982      4 -rw-r--r--   1 root     root          920 Jan 12  2007 /etc/X11/app-defaults/Xmessage-color
     8981      4 -rw-r--r--   1 root     root          248 Jan 12  2007 /etc/X11/app-defaults/Xmessage
     9453      4 -rw-r--r--   1 root     root         3796 Sep  2  2006 /etc/X11/app-defaults/SshAskpass
     9368      4 -rwxr-xr-x   1 root     root          144 Mar  6  2007 /etc/apm/event.d/gpm
     9384      4 -rwxr-xr-x   1 root     root         2265 Feb 16  2007 /etc/apm/event.d/20hdparm
     9159      4 -rwxr-xr-x   1 root     root          753 Oct 14  2006 /etc/apm/event.d/anacron
     7289      4 -rwxr-xr-x   1 root     root         3849 Feb 25  2007 /etc/apm/apmd_proxy
      175      4 -rw-r--r--   1 root     root          182 Dec 20  2006 /etc/apt/apt.conf.d/70debconf
       10      4 -rw-r--r--   1 root     root           40 Dec 17  2007 /etc/apt/apt.conf.d/00trustcdrom
     9923      4 -rw-r--r--   1 root     root           48 Dec 17  2007 /etc/apt/listbugs/ignore_bugs
      393      0 -rw-r--r--   1 root     root            0 Dec 17  2007 /etc/apt/sources.list~
     6178      0 drwxr-xr-x   2 root     root           48 Dec 17  2007 /etc/opt
      401      4 -rwxr-xr-x   1 root     root          268 Dec  1  2006 /etc/rmt
     6265      4 -rw-r--r--   1 root     root          887 Feb  1  2007 /etc/rpc
     7334      0 -rw-r--r--   1 root     root            0 Dec 13  2005 /etc/resolvconf/resolv.conf.d/base
     7377      0 -rw-r--r--   1 root     root            0 Dec 18  2007 /etc/resolvconf/resolv.conf.d/tail
     7378      4 -rw-r--r--   1 root     root           51 Dec 18  2007 /etc/resolvconf/resolv.conf.d/original
     9238      4 -rw-r--r--   1 root     root          260 Jan 18  2006 /etc/dpkg/shlibs.default
      194      4 -rw-r--r--   1 root     root           82 Jan  2  2007 /etc/dpkg/origins/debian
     9237      4 -rw-r--r--   1 root     root          253 Jan 18  2006 /etc/dpkg/shlibs.override
     9337      0 drwxr-xr-x   3 root     root           72 Dec 17  2007 /etc/gimp
     9225      4 -rw-r--r--   1 root     root         2489 Jan  2  2007 /etc/java/security/classpath.security
     9221      0 -rw-r--r--   1 root     root            0 Jan  2  2007 /etc/java/security/security.d/1001-gnu.javax.crypto.jce.GnuCrypto
     9220      0 -rw-r--r--   1 root     root            0 Jan  2  2007 /etc/java/security/security.d/1000-gnu.java.security.provider.Gnu
     9223      0 -rw-r--r--   1 root     root            0 Jan  2  2007 /etc/java/security/security.d/1003-gnu.javax.net.ssl.provider.Jessie
     9222      0 -rw-r--r--   1 root     root            0 Jan  2  2007 /etc/java/security/security.d/1002-gnu.javax.crypto.jce.GnuSasl
     9224      0 -rw-r--r--   1 root     root            0 Jan  2  2007 /etc/java/security/security.d/1004-gnu.javax.security.auth.callback.GnuCallbacks
     9359      4 -rw-r--r--   1 root     root          127 Sep 10  2005 /etc/kde3/konqsidebartng.rc
     9419      4 -rw-r--r--   1 root     root         1010 Sep 10  2005 /etc/kde3/kmail.antivirusrc
     9269      0 drwxr-xr-x   2 root     root           48 Dec 17  2007 /etc/keys
     9086      0 drwxr-xr-x   3 root     root           72 Dec 17  2007 /etc/perl/XML
      214      4 -rw-r--r--   1 root     root          220 Dec 11  2006 /etc/skel/.bash_logout
     7280      4 -rw-r--r--   1 root     root          216 Feb 25  2007 /etc/default/apmd
     9271      4 -rw-r--r--   1 root     root           54 Dec 17  2007 /etc/crypttab
     9893      0 lrwxrwxrwx   1 root     root           12 Dec 17  2007 /etc/alternatives/rsh -> /usr/bin/ssh
      190      4 -rw-r--r--   1 root     root          100 Jan  2  2007 /etc/alternatives/README
     6521      0 lrwxrwxrwx   1 root     root           12 Dec 18  2007 /etc/alternatives/lvm-default -> /lib/lvm-200
     9902      0 lrwxrwxrwx   1 root     root           28 Dec 17  2007 /etc/alternatives/rsh.1.gz -> /usr/share/man/man1/ssh.1.gz
     9430      4 -rw-r--r--   1 root     root           31 Dec 22  2006 /etc/menu-methods/menu.config
     8461      4 -rw-r--r--   1 root     root          729 Jan 17  2007 /etc/emacs/site-start.d/50autoconf.el
     9328      0 drwxr-xr-x   5 root     root          152 Dec 17  2007 /etc/gconf
     9330      4 -rw-r--r--   1 root     root         3397 Feb 26  2007 /etc/gconf/2/evoldap.conf
     9331      0 drwxr-xr-x   2 root     root           80 Dec 17  2007 /etc/gconf/gconf.xml.mandatory
     9990      0 -rw-r--r--   1 root     root            0 Dec 17  2007 /etc/gconf/gconf.xml.mandatory/%gconf-tree.xml
     9332      0 drwxr-xr-x   2 root     root           80 Dec 17  2007 /etc/gconf/gconf.xml.defaults
     9991      0 -rw-r--r--   1 root     root            0 Dec 17  2007 /etc/gconf/gconf.xml.defaults/%gconf-tree.xml
     8919      4 -rw-r--r--   1 root     root          514 Feb 22  2007 /etc/fonts/conf.avail/30-amt-aliases.conf
     8917      4 -rw-r--r--   1 root     root          301 Feb 22  2007 /etc/fonts/conf.avail/20-lohit-gujarati.conf
     8921      4 -rw-r--r--   1 root     root         1723 Feb 22  2007 /etc/fonts/conf.avail/40-generic.conf
     8888      4 -rw-r--r--   1 root     root          111 Sep 12  2007 /etc/magic
      359      4 -rw-r--r--   1 root     root          384 Feb 27  2007 /etc/pam.d/chfn
      360      4 -rw-r--r--   1 root     root          581 Feb 27  2007 /etc/pam.d/chsh
       83      4 -rw-r--r--   1 root     root          520 Aug 31  2003 /etc/pam.d/other
      358      4 -rw-r--r--   1 root     root           92 Feb 27  2007 /etc/pam.d/passwd
     9445      4 -rw-r--r--   1 root     root            8 May 30  2007 /etc/samba/gdbcommands
     9421      0 drwxr-xr-x   3 root     root           72 Dec 17  2007 /etc/sound
     9365     12 -rw-r--r--   1 root     root        10852 Nov  7  2006 /etc/gnome-vfs-mime-magic
     6468      4 -rwxr-xr-x   1 root     root           89 Apr  8  2006 /etc/cron.daily/logrotate
     6260      4 -rwxr-xr-x   1 root     root          314 Mar 14  2007 /etc/cron.daily/aptitude
     9154      4 -rwxr-xr-x   1 root     root          311 Oct 14  2006 /etc/cron.daily/0anacron
     6323      4 -rw-r--r--   1 root     root          102 Dec 19  2006 /etc/cron.daily/.placeholder
       81      4 -rw-r--r--   1 root     root          552 Jul 31  2004 /etc/pam.conf
     6326      4 -rw-r--r--   1 root     root          102 Dec 19  2006 /etc/cron.hourly/.placeholder
     7428      4 -rw-r--r--   1 root     root          588 Jan 27  2007 /etc/GeoIP.conf.default
     7389      0 lrwxrwxrwx   1 root     root           22 Dec 18  2007 /etc/auto-apt/sources.list -> /etc/apt//sources.list
     9412      4 -rw-r--r--   1 root     root          112 Oct  2  2006 /etc/iproute2/rt_realms
     9411      4 -rw-r--r--   1 root     root           92 Oct  2  2006 /etc/iproute2/rt_scopes
     9410      4 -rw-r--r--   1 root     root           87 Oct  2  2006 /etc/iproute2/rt_tables
     9063      4 -rw-r--r--   1 root     root          125 Mar 16  2006 /etc/mail.rc
     8505      4 -rwxr-xr-x   1 root     root           65 Jan 17  2007 /etc/cron.monthly/vrms
     9156      4 -rwxr-xr-x   1 root     root          313 Oct 14  2006 /etc/cron.monthly/0anacron
     6318      4 -rw-r--r--   1 root     root          102 Dec 19  2006 /etc/cron.monthly/.placeholder
     8493      4 -rw-r--r--   1 root     root         3287 Feb  1  2005 /etc/iceweasel/profile/search.rdf
       38      4 -rw-r--r--   1 root     root         1260 Feb 25  2007 /etc/ucf.conf
     6332      4 -rw-r--r--   1 root     root          612 Jan  2  2007 /etc/calendar/default
     9155      4 -rwxr-xr-x   1 root     root          312 Oct 14  2006 /etc/cron.weekly/0anacron
     6328      4 -rw-r--r--   1 root     root          102 Dec 19  2006 /etc/cron.weekly/.placeholder
     6516      4 -rw-r--r--   1 root     root          677 Dec 17  2007 /etc/hosts.allow
     8898     36 -rw-r--r--   1 root     root        33286 Oct 23  2006 /etc/defoma/hints/gsfonts.hints
     8896      8 -rw-r--r--   1 root     root         4107 Jul 19  2006 /etc/defoma/hints/ttf-bitstream-vera.hints
     6321      4 -rw-r--r--   1 root     root          102 Dec 19  2006 /etc/cron.d/.placeholder
     7404      4 -rw-r--r--   1 root     root         2064 Nov 23  2006 /etc/netscsid.conf
     9065      4 -rw-r--r--   1 root     root          449 Dec  4  2006 /etc/mailcap.order
     6261      4 -rw-r--r--   1 root     root           79 Mar 14  2007 /etc/logrotate.d/aptitude
      153      0 -rw-------   1 root     root            0 Dec 17  2007 /etc/.pwd.lock
     9941      4 -rw-r--r--   1 root     root            7 Dec 17  2007 /etc/papersize
     9873      0 drwxr-xr-x   2 root     root           80 Dec 17  2007 /etc/python
     9875      4 -rw-r--r--   1 root     root           94 Dec 17  2007 /etc/python/debian_config
     9389      4 -rw-r--r--   1 root     root           38 Dec 18  2006 /etc/sane.d/dll.d/hplip
     6591      4 -rw-r--r--   1 root     root           60 Dec 17  2007 /etc/networks
     6835      0 drwxr-xr-x   2 root     root           72 Dec 17  2007 /etc/initramfs-tools/conf.d
     6780      4 -rw-r--r--   1 root     root           32 Dec 17  2007 /etc/initramfs-tools/conf.d/resume
     6860      4 -rw-r--r--   1 root     root          191 Dec 17  2007 /etc/initramfs-tools/modules
     8457      4 -rw-r-----   1 root     daemon        144 Mar 18  2006 /etc/at.deny
      229      4 -rw-r--r--   1 root     root         2803 Dec 17  2007 /etc/adduser.conf
     9353      4 -rw-r--r--   1 root     root         3695 Sep 12  2007 /etc/hotplug/usb/logitechmouse.usermap
     9352      4 -rwxr-xr-x   1 root     root          252 Sep 12  2007 /etc/hotplug/usb/logitechmouse
     6575      4 -rw-r--r--   1 root     root          901 Dec 17  2007 /etc/hosts.deny
     6243      4 -rw-r--r--   1 root     root         2008 Jan 30  2007 /etc/inittab
      164      4 -rw-r--r--   1 root     root         1723 Dec 19  2006 /etc/inputrc
      204      4 -rw-r--r--   1 root     root            9 Aug  7  2006 /etc/host.conf
     7410      4 -rw-r--r--   1 root     root         1343 Jan  9  2007 /etc/wodim.conf
     9978      4 -rw-r--r--   1 root     root          600 Dec 18  2007 /etc/gpm.conf
     6197      4 -rwxr-xr-x   1 root     root          306 Dec 17  2007 /etc/rc.local
      306      0 drwxr-xr-x  15 root     root          360 Dec 17  2007 /lib/terminfo
     9226      0 drwxr-xr-x   3 root     root           80 Dec 17  2007 /emul
     9228      0 drwxr-xr-x   3 root     root           72 Dec 17  2007 /emul/ia32-linux/usr
     6173      4 -rw-r--r--   1 root     root          412 Dec 15  2004 /root/.bashrc
     6172      4 -rw-r--r--   1 root     root          110 Nov 10  2004 /root/.profile
       14      0 lrwxrwxrwx   1 root     root           11 Dec 17  2007 /cdrom -> media/cdrom
       12      0 lrwxrwxrwx   1 root     root            6 Dec 17  2007 /media/cdrom -> cdrom0
       16      0 drwxr-xr-x   2 root     root           48 Dec 17  2007 /media/floppy0
       13      0 drwxr-xr-x   2 root     root           48 Dec 17  2007 /media/cdrom0
       15      0 lrwxrwxrwx   1 root     root            7 Dec 17  2007 /media/floppy -> floppy0
     6179      0 drwxr-xr-x   2 root     root           48 Dec 17  2007 /initrd

Attachment: signature.asc
Description: This is a digitally signed message part.

Reply via email to